🎯 Goal

The focus of today’s study was understanding how phishing campaigns operate and how defenders analyze email infrastructure to identify malicious activity.


πŸ›  What I Did

Studied Phishing Attack Structure

Phishing attacks rely on impersonation to trick victims into revealing sensitive information.

Attackers commonly impersonate:

β€’ banks
β€’ online services
β€’ company IT departments
β€’ internal executives

The goal is typically to steal credentials or deliver malware.


Explored Email Security Mechanisms

Several technologies help protect against phishing.

These include:

β€’ SPF (Sender Policy Framework)
β€’ DKIM (DomainKeys Identified Mail)
β€’ DMARC (Domain-based Message Authentication)

These technologies help verify whether an email was legitimately sent from a specific domain.


πŸ”— Key Cybersecurity Connections

SOC analysts frequently investigate phishing incidents by analyzing:

β€’ sender domains
β€’ email headers
β€’ attachment hashes
β€’ URL reputation

These elements help determine whether an email is malicious.


πŸ” Investigation Questions

When analyzing a potential phishing email, investigators might ask:

  • What domain and IP address sent the email?
  • Did the message pass SPF, DKIM, and DMARC authentication checks?
  • Is the sender domain newly registered or similar to a legitimate domain (typosquatting)?
  • Do the embedded links point to look-alike login pages or suspicious infrastructure?
  • Did any users click the link or download the attachment?
  • Are there multiple emails with the same indicators across the organization?

These questions help analysts determine whether the message is part of a broader phishing campaign.


🚨 Detection Opportunities

Several detection opportunities exist when analyzing phishing activity:

  • detecting SPF, DKIM, or DMARC failures
  • monitoring newly registered or suspicious domains
  • identifying emails containing known malicious URLs
  • detecting attachments with malicious hashes
  • correlating email delivery with user click events or credential submissions

Useful telemetry sources include:

  • email gateway logs
  • DNS logs
  • web proxy logs
  • endpoint telemetry.

🧭 MITRE ATT&CK Techniques

Phishing campaigns commonly involve the following MITRE ATT&CK techniques:

  • T1566 β€” Phishing
  • T1566.001 β€” Spearphishing Attachment
  • T1566.002 β€” Spearphishing Link
  • T1583 β€” Acquire Infrastructure
  • T1584 β€” Compromise Infrastructure

These techniques represent how attackers use social engineering and infrastructure control to gain initial access.


⚠ Challenges

Attackers Constantly Adapt

Phishing campaigns evolve rapidly.

Attackers frequently register new domains and modify email content to bypass detection.


πŸ“š What I Learned

Social engineering is a major attack vector

Many successful intrusions begin with phishing emails rather than technical exploits.

This makes phishing detection a critical component of organizational security.


➑ Next Steps

Future study will involve analyzing malicious attachments and investigating how phishing payloads execute on victim machines.


🧠 Reflection

Phishing attacks highlight the importance of combining technical detection with user awareness.

Even well-secured systems can be compromised if users are deceived by convincing social engineering techniques.


🧩 Lessons Learned

What worked

Understanding phishing infrastructure clarified how attackers impersonate trusted entities.

What broke

Email spoofing techniques can make malicious emails appear legitimate.

Why it broke

Email systems historically lacked strong authentication mechanisms.

Fix / takeaway

Always verify sender domains and email authentication mechanisms.


πŸ“ˆ Skill Progression Context

Phishing investigation skills are critical for:

β€’ SOC Analysts
β€’ Incident Responders
β€’ Email Security Engineers